CVE-2022-50999: Nokogiri before 1.13.5 Integer Overflow via libxml2

Published Aug 25, 2026
·
Updated

Nokogiri versions before 1.13.5 contain an integer overflow vulnerability in packaged libxml2 buffer handling functions that allows attackers to cause out-of-bounds memory writes. Attackers can exploit this by crafting multi-gigabyte XML files to trigger buffer overflows resulting in information disclosure, data modification, or denial of service.

Affected Software

1 affected component
rubygems/nokogiri<1.13.5

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade nokogiri to a version that resolves this vulnerability.

    Fixed in 1.13.5

Event History

Aug 25, 2026
CVE Published
via MITRE·03:15 PM
Data Sourced
via MITRE·03:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What must an attacker be able to do to exploit this issue?

An attacker needs to supply a crafted multi-gigabyte XML file that is processed by the affected Nokogiri installation. No authentication or user interaction is required according to the supplied severity vector.

2

Which deployments are most exposed?

Deployments using the rubygems/nokogiri package before version 1.13.5 that parse attacker-controlled or otherwise untrusted XML are exposed. The issue is remotely exploitable where an attacker can cause such XML to be processed.

3

What should be done if upgrading cannot happen immediately?

Prevent untrusted multi-gigabyte XML documents from reaching Nokogiri parsing paths, including by enforcing input-size limits before parsing. This reduces the ability to trigger the vulnerable libxml2 buffer-handling behavior.

4

What impact should responders consider?

Successful exploitation can cause out-of-bounds memory writes, with potential information disclosure, data modification, or denial of service. Availability impact is rated high, while confidentiality and integrity impacts are rated low in the provided vector.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203